revert(vds-nftables): restore original config — T3 fix needs discussion

Owner request 2026-10-10: 'отмени вообще правки файрволла, верни
пока какие были до твоих работ. это требует обсуждения, потому
что по прежнему ничего не работает, сайт не открывается,
reality не работает.'

This reverts 5 T3 code commits + 2 T3 doc commits:
  5796786 fix(vds-nftables): apply Option A
  3deaa75 fix(vds-nftables): remove allowPing
  4dc4849 fix(vds-nftables): open SSH on all interfaces
  2649e2f fix(vds-nftables): open port 80
  51ea19a fix(vds-nftables): open port 8443
  677d39e docs(T3): note correction
  fafd3e2 docs(T3): mark nftables fix as applied

Restored:
- configurations/vds.nix → original from 61b3724 (firewall.enable = true,
  firewall.interfaces.tailscale0.allowedTCPPorts = [22], nftables with
  SYN rate-limit on {80,443})
- .agent/tasks/manifest.json T3 → status = 'pending' (was 'completed')
- .agent/decisions/index.json T3-A → status = 'proposed' (was 'accepted')

The proposal .agent/decisions/proposals/vds-nftables-fix.md is NOT
removed — it's still a proposal for future discussion, just not
applied. nft list ruleset on otreca will return to the original
(firewall-managed) state after rebuild.

T3 needs proper discussion with owner before re-applying. The
issues observed (site not opening, reality not working) need
diagnostic before any new fix attempt.
This commit is contained in:
2026-10-10 17:30:58 +03:00
parent 51ea19aef4
commit 37b4956a25
3 changed files with 21 additions and 71 deletions
+2 -2
View File
@@ -50,7 +50,7 @@
"id": "T3",
"title": "A3: явная финальная политика nftables на VDS",
"type": "fix",
"status": "completed",
"status": "pending",
"origin": "user:direct",
"depends_on": [],
"acceptance_criteria": [
@@ -60,7 +60,7 @@
],
"files": ["configurations/vds.nix"],
"blocks": ["T11", "T12"],
"notes": "Applied 2026-10-10. 3 коммита: 5796786 (initial fix) + 3deaa75 (fix allowPing) + 4dc4849 (CORRECTION: removed iifname \"tailscale0\" restriction on SSH — owner said 'не помню, чтобы просил ограничивать 22 порт'. SSH now on all interfaces). Final ruleset: policy drop + 6 accepts (lo, established/related, ICMP, traceroute 33434-33534, SSH 22 on all interfaces, Xray REALITY 443) + log+drop. firewall.enable = false (R1.6 conflict resolved). lib.mkForce on allowedTCPPorts/interfaces prevents shadow rules. Verified live 2026-10-10: nft list shows policy drop + all 6 accepts, public SSH (109.248.161.5:22) works, Tailscale SSH (100.64.1.0:22) works, Xray 443 listening."
"notes": "REVERTED 2026-10-10: owner requested revert of all T3 firewall changes. 'по прежнему ничего не работает, сайт не открывается, reality не работает. это требует обсуждения.' Original vds.nix restored (commit 61b3724 baseline). 5 T3 commits reverted: 5796786, 3deaa75, 4dc4849, 2649e2f, 51ea19a + docs 677d39e, fafd3e2. Requires discussion before re-applying."
},
{
"id": "T4",